Skip to content
Hotwireless

Guest WiFi security

Is your Guest WiFi safe?

A 60-second check for South African venues that hand out the same WiFi password to everyone. No tech knowledge needed.

Free WiFi keeps customers happy, but the way most venues set it up quietly puts the business and its guests at risk. One shared password on one flat network is all it takes.

The 60-second check

Tick every box that is true for your venue.

Six questions. Your score updates as you go, and nothing you tick is stored or sent anywhere.

The 60-second guest WiFi check

Your score

You’ve ticked 0 of 6

Tick what applies. Your score updates as you go.

Why it matters

What these risks actually mean.

None of this needs a hacker. It is what a shared password on one flat network does on an ordinary Tuesday.

A shared password is an open door.

Anyone who has ever seen it can join again from the car park months later, on your line and inside your network. Former staff, the delivery driver, the table that left in March. The password does not know who it is letting in.

One flat network exposes your business.

If guests are on the same network as your till, card machine, office computer or cameras, a guest device is sitting alongside the systems your business runs on. Those systems were never meant to share a network with whoever walked in for a coffee.

Guest data is your responsibility under POPIA.

If names, numbers or email addresses are captured on your WiFi, you are the responsible party for that information. That means consent at the point it is collected, a reason for holding it, and a way to answer if a guest or the Information Regulator asks how you look after it.

The fix

What ‘done right’ looks like.

Five things you get on every Hotwireless venue. Nothing on this list is a promise for later.

How the login page works →
  • A separate guest network Walled off from your till, card machine, office PC and cameras. Guests reach the internet, not your side of the router.
  • No shared password Every guest goes through your own branded login page and accepts your terms of use. There is nothing written on the wall to walk out of the building.
  • Access that expires Session limits instead of access that lasts forever. When the session ends, so does the connection.
  • We can see who is connected — and so can you A list in your own login if you want one, not a rumour.
  • The router is ours to look after Supplied, kept updated and monitored by us, so the question of who last updated it has an answer.

The bigger picture

Cyber crime in South Africa is rising.

Every figure below carries its source. If it is not sourced, it is not on this page.

Your obligations

What the law expects of you.

Plain-English summaries, each linked to the Act itself. This is orientation, not legal advice.

  • Sections 1 and 19(1)

    Protection of Personal Information Act 4 of 2013 (POPIA)

    If guest details are captured on your WiFi, you are the "responsible party". You must take appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unlawful access to that information.

    Protection of Personal Information Act 4 of 2013 (POPIA) — Sections 1 and 19(1)

  • Section 19(2)

    POPIA

    You must identify all reasonably foreseeable internal and external risks, put safeguards in place, check that they work, and keep them updated. In our view, a guest network that reaches your till and office PC is a foreseeable risk.

    POPIA — Section 19(2)

  • Section 22

    POPIA

    When personal information is accessed by someone who should not have it, you must notify the Information Regulator and the people affected as soon as reasonably possible. The Regulator says the compromise does not have to be confirmed before it is reported.

    POPIA — Section 22

  • Sections 107 and 109

    POPIA

    Administrative fines can reach R10 million (section 109). The most serious offences under the Act carry imprisonment of up to 10 years (section 107).

    POPIA — Sections 107 and 109

  • Requirement 1.3.3

    PCI DSS v4.0.1 (the card industry's security standard)

    Network security controls must sit between any wireless network and the environment where card data is handled. A card machine on the same open WiFi as your guests is exactly what Requirement 1.3.3 is written to prevent.

    PCI DSS v4.0.1 (the card industry's security standard) — Requirement 1.3.3

  • Section 2.1.2

    NIST Special Publication 800-153, Guidelines for Securing Wireless Local Area Networks

    Guest and internal WiFi should be separate networks, and devices on the guest network should not be able to reach internal devices or send their traffic across the internal network.

    NIST Special Publication 800-153, Guidelines for Securing Wireless Local Area Networks — Section 2.1.2

Not sure where you stand?

Book the walkthrough and we check your setup with you.

Or call us on 071 437 6694